ISO 27001 and ISO 42001. Implement it, or audit it.
ISMS (Information Security Management System) and AIMS (AI Management System) are the ISO standards that prove your business is serious. We work either side of the line: building the management system, documentation and evidence trail, or auditing a system somebody else built. What we will not do is both on the same system, because an audit is only worth something if the person running it had no hand in the thing being audited.
ISO 27001 has been around two decades and is now table stakes for serious procurement. ISO 42001 is brand new and almost no Australian business has even started - which is exactly why now is the right time. We help with both.
ISMS - ISO 27001
The standard most procurement teams now ask for. Proves you treat information security like a system, not a series of fires.
AIMS - ISO 42001
Published in 2023. The first ISO standard purpose-built for AI governance. Almost no business is certified yet - early movers will be ahead of the curve.
Where you currently stand against ISO 27001 (ISMS) or ISO 42001 (AIMS), what's missing, and the order to close those gaps in.
Policies, procedures and statements of applicability written for your business - not boilerplate copied from a template that won't survive an auditor's first question.
The records and artefacts an auditor wants to see, organised the way they want to see them. Get the certification conversation off on the right foot.
Auditing a management system we had no hand in building. Where the implementation was ours, an independent practitioner we work with takes the audit instead.
AIMS is new - most businesses don't yet know what's required. We help you stand up the AI governance, risk and lifecycle controls before regulators or customers ask.
Agree what's in and out of the management system, who the stakeholders are, and which clauses of the standard genuinely apply to your business.
Write the documentation, build the controls, and capture the evidence in a way that holds up under audit scrutiny.
When you're ready, we help you engage a certification body and stand alongside you through the stage 1 and stage 2 audit. Where we built the system, the audit goes to an independent practitioner rather than back to us.
Project consulting, technology recommendations, and custom builds when off-the-shelf doesn't fit.
AWS and Azure, both directly. Partner status on each, live clients on each, and no preference to sell you.
SIEM and XDR setup, posture reviews, and the compliance work the auditors and insurers care about.